nerdexam
GIAC

GCFA · Question #276

You work as a Network Administrator for NetTech Inc. The company has a network that consists of 200 client computers and ten database servers. One morning, you find that an unauthorized user is…

The correct answer is A. Prevent the company employees from entering the server room. B. Detach the network cable from the database server. D. Preserve the log files for a forensics expert. Proper incident response to unauthorized database access requires isolating the affected system, controlling physical access to the scene, and preserving digital evidence such as log files for forensic analysis.

Advanced Incident Response & Digital Forensics Fundamentals

Question

You work as a Network Administrator for NetTech Inc. The company has a network that consists of 200 client computers and ten database servers. One morning, you find that an unauthorized user is accessing data on a database server on the network. Which of the following actions will you take to preserve the evidences? Each correct answer represents a complete solution. Choose three.

Options

  • APrevent the company employees from entering the server room.
  • BDetach the network cable from the database server.
  • CPrevent a forensics experts team from entering the server room.
  • DPreserve the log files for a forensics expert.

How the community answered

(27 responses)
  • A
    70% (19)
  • C
    30% (8)

Why each option

Proper incident response to unauthorized database access requires isolating the affected system, controlling physical access to the scene, and preserving digital evidence such as log files for forensic analysis.

APrevent the company employees from entering the server room.Correct

Restricting unauthorized company employees from the server room prevents tampering with physical evidence and maintains the integrity of the incident scene, which is a foundational step in evidence preservation.

BDetach the network cable from the database server.Correct

Detaching the network cable from the database server immediately stops ongoing unauthorized access and preserves the current system state, preventing further data exfiltration or evidence destruction by the attacker.

CPrevent a forensics experts team from entering the server room.

Preventing forensics experts from entering the server room directly obstructs the investigation - forensics teams must be granted access to properly collect, document, and analyze evidence from the compromised server.

DPreserve the log files for a forensics expert.Correct

Preserving log files is critical digital evidence collection - logs contain records of the unauthorized user's actions, timestamps, and access patterns that a forensics expert needs for attribution and analysis.

Concept tested: Incident response digital evidence preservation steps

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r2.pdf

Topics

#evidence preservation#incident response#chain of custody#log files

Community Discussion

No community discussion yet for this question.

Full GCFA Practice